CVE-2021-27068 is a Remote Code Execution vulnerability affecting Microsoft Visual Studio 2019. With a CVSS score of 8.8 (HIGH), it allows an authenticated attacker to execute arbitrary code remotely with low attack complexity and no user interaction, leading to high impact on confidentiality, integrity, and availability. Despite its high severity and a FAUCET Risk Score of 90/100, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal, with only one mention and one article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.0, < 16.4.22CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* | ||
>= 16.5.0, < 16.7.15CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* | ||
>= 16.8.0, < 16.9.5CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.